diff --git a/findings/README.md b/findings/README.md index 1c2cf67..5b556d0 100644 --- a/findings/README.md +++ b/findings/README.md @@ -43,4 +43,15 @@ it is and who hears about it (`INTENT.md`). Leaving them out, or writing - **A note is fine.** If it would not change anyone's decision, it belongs in `notes/` — see the floor in `docs/method/severity.md`. +## Asking for a tenant-boundary verification + +Separate from filing. The estate carries `RISK-F-0007` — no consumer's tenant +boundary is verified anywhere — as an accepted risk until production, on the +operator's ruling of 2026-08-19, with verification available **on request**. + +Message `risk-nexus` naming one consumer boundary and what would have to be +true of it. The owning repo of that consumer does the verification; this repo +scopes and records it and verifies nothing itself. A boundary that holds is +evidence; one that does not is a finding with its own owner. + After filing: `make check`. Then this repo grades it.